D
dm4327
Hello,
My computer was recently attacked using vulnerabilities in
RPC / Microsoft DCOM. I have since read Microsoft Security
Bulletin MS03-026
[Buffer Overrun In RPC Interface Could Allow Code
Execution (823980)]
and have installed the recommended patch. I have also
installed a Sygate firewall to prevent further attacks.
However, I was looking through "System Information" in the
Microsoft system tools folder and I noticed some strange
changes, which I do not know how to fix. I have pasted
the log below. Any help would be appreciated. Thank you
in advance!
09/08/2003 16:39:02 ADDED msblast.exe
Startup Programs
11/08/2003 22:37:53 CHANGED Accessories
Property "UserName" changed from "Default User"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "Name" changed from "Default
User:Accessories" to "All Users:Accessories". Program
Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "UserName" changed from "Default User"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "Name" changed from "Default
User:Accessories\Accessibility" to "All
Users:Accessories\Accessibility". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "UserName" changed from "Default User"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "Name" changed from "Default
User:Accessories\Entertainment" to "All
Users:Accessories\Entertainment". Program Group
11/08/2003 22:37:53 CHANGED Startup
Property "UserName" changed from "Default User"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Startup Property "Name"
changed from "Default User:Startup" to "All Users:Startup".
Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "UserName" changed from "NT
AUTHORITY\SYSTEM" to "Default User". Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "Name" changed from "NT
AUTHORITY\SYSTEM:Accessories" to "Default
User:Accessories". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "UserName" changed from "NT
AUTHORITY\SYSTEM" to "Default User". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "Name" changed from "NT
AUTHORITY\SYSTEM:Accessories\Accessibility" to "Default
User:Accessories\Accessibility". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "UserName" changed from "NT
AUTHORITY\SYSTEM" to "Default User". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "Name" changed from "NT
AUTHORITY\SYSTEM:Accessories\Entertainment" to "Default
User:Accessories\Entertainment". Program Group
11/08/2003 22:37:53 CHANGED Startup
Property "UserName" changed from "NT
AUTHORITY\SYSTEM" to "Default User". Program Group
11/08/2003 22:37:53 CHANGED Startup Property "Name"
changed from "NT AUTHORITY\SYSTEM:Startup" to "Default
User:Startup". Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "UserName" changed from "OEM\OEMUSER"
to "NT AUTHORITY\SYSTEM". Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "Name" changed
from "OEM\OEMUSER:Accessories" to "NT
AUTHORITY\SYSTEM:Accessories". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "UserName" changed from "OEM\OEMUSER"
to "NT AUTHORITY\SYSTEM". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "Name" changed
from "OEM\OEMUSER:Accessories\Accessibility" to "NT
AUTHORITY\SYSTEM:Accessories\Accessibility". Program
Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "UserName" changed from "OEM\OEMUSER"
to "NT AUTHORITY\SYSTEM". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "Name" changed
from "OEM\OEMUSER:Accessories\Entertainment" to "NT
AUTHORITY\SYSTEM:Accessories\Entertainment". Program
Group
11/08/2003 22:37:53 CHANGED Administrative Tools
Property "UserName" changed from "OEM\OEMUSER"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Administrative Tools
Property "Name" changed
from "OEM\OEMUSER:Administrative Tools" to "All
Users:Administrative Tools". Program Group
11/08/2003 22:37:53 CHANGED Startup
Property "UserName" changed from "OEM\OEMUSER"
to "NT AUTHORITY\SYSTEM". Program Group
11/08/2003 22:37:53 CHANGED Startup Property "Name"
changed from "OEM\OEMUSER:Startup" to "NT
AUTHORITY\SYSTEM:Startup". Program Group
11/08/2003 22:37:53 CHANGED C:\WINDOWS\System32
\CTFMON.EXE Property "User" changed from "NT
AUTHORITY\SYSTEM" to ".DEFAULT". Startup Programs
11/08/2003 22:37:53 CHANGED C:\WINDOWS\System32
\CTFMON.EXE Property "Location" changed from "HKU\S-1-
5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
to "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run". Startup Programs
11/08/2003 22:37:53 CHANGED desktop.ini
Property "User" changed from ".DEFAULT" to "All
Users". Startup Programs
11/08/2003 22:37:53 CHANGED desktop.ini
Property "Location" changed from "Startup"
to "Common Startup". Startup Programs
11/08/2003 22:37:53 CHANGED desktop.ini
Property "User" changed from "NT AUTHORITY\SYSTEM"
to ".DEFAULT". Startup Programs
11/08/2003 22:37:53 CHANGED desktop.ini
Property "User" changed from "OEM\OEMUSER" to "NT
AUTHORITY\SYSTEM". Startup Programs
My computer was recently attacked using vulnerabilities in
RPC / Microsoft DCOM. I have since read Microsoft Security
Bulletin MS03-026
[Buffer Overrun In RPC Interface Could Allow Code
Execution (823980)]
and have installed the recommended patch. I have also
installed a Sygate firewall to prevent further attacks.
However, I was looking through "System Information" in the
Microsoft system tools folder and I noticed some strange
changes, which I do not know how to fix. I have pasted
the log below. Any help would be appreciated. Thank you
in advance!
09/08/2003 16:39:02 ADDED msblast.exe
Startup Programs
11/08/2003 22:37:53 CHANGED Accessories
Property "UserName" changed from "Default User"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "Name" changed from "Default
User:Accessories" to "All Users:Accessories". Program
Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "UserName" changed from "Default User"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "Name" changed from "Default
User:Accessories\Accessibility" to "All
Users:Accessories\Accessibility". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "UserName" changed from "Default User"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "Name" changed from "Default
User:Accessories\Entertainment" to "All
Users:Accessories\Entertainment". Program Group
11/08/2003 22:37:53 CHANGED Startup
Property "UserName" changed from "Default User"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Startup Property "Name"
changed from "Default User:Startup" to "All Users:Startup".
Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "UserName" changed from "NT
AUTHORITY\SYSTEM" to "Default User". Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "Name" changed from "NT
AUTHORITY\SYSTEM:Accessories" to "Default
User:Accessories". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "UserName" changed from "NT
AUTHORITY\SYSTEM" to "Default User". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "Name" changed from "NT
AUTHORITY\SYSTEM:Accessories\Accessibility" to "Default
User:Accessories\Accessibility". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "UserName" changed from "NT
AUTHORITY\SYSTEM" to "Default User". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "Name" changed from "NT
AUTHORITY\SYSTEM:Accessories\Entertainment" to "Default
User:Accessories\Entertainment". Program Group
11/08/2003 22:37:53 CHANGED Startup
Property "UserName" changed from "NT
AUTHORITY\SYSTEM" to "Default User". Program Group
11/08/2003 22:37:53 CHANGED Startup Property "Name"
changed from "NT AUTHORITY\SYSTEM:Startup" to "Default
User:Startup". Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "UserName" changed from "OEM\OEMUSER"
to "NT AUTHORITY\SYSTEM". Program Group
11/08/2003 22:37:53 CHANGED Accessories
Property "Name" changed
from "OEM\OEMUSER:Accessories" to "NT
AUTHORITY\SYSTEM:Accessories". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "UserName" changed from "OEM\OEMUSER"
to "NT AUTHORITY\SYSTEM". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Accessibility
Property "Name" changed
from "OEM\OEMUSER:Accessories\Accessibility" to "NT
AUTHORITY\SYSTEM:Accessories\Accessibility". Program
Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "UserName" changed from "OEM\OEMUSER"
to "NT AUTHORITY\SYSTEM". Program Group
11/08/2003 22:37:53 CHANGED Accessories\Entertainment
Property "Name" changed
from "OEM\OEMUSER:Accessories\Entertainment" to "NT
AUTHORITY\SYSTEM:Accessories\Entertainment". Program
Group
11/08/2003 22:37:53 CHANGED Administrative Tools
Property "UserName" changed from "OEM\OEMUSER"
to "All Users". Program Group
11/08/2003 22:37:53 CHANGED Administrative Tools
Property "Name" changed
from "OEM\OEMUSER:Administrative Tools" to "All
Users:Administrative Tools". Program Group
11/08/2003 22:37:53 CHANGED Startup
Property "UserName" changed from "OEM\OEMUSER"
to "NT AUTHORITY\SYSTEM". Program Group
11/08/2003 22:37:53 CHANGED Startup Property "Name"
changed from "OEM\OEMUSER:Startup" to "NT
AUTHORITY\SYSTEM:Startup". Program Group
11/08/2003 22:37:53 CHANGED C:\WINDOWS\System32
\CTFMON.EXE Property "User" changed from "NT
AUTHORITY\SYSTEM" to ".DEFAULT". Startup Programs
11/08/2003 22:37:53 CHANGED C:\WINDOWS\System32
\CTFMON.EXE Property "Location" changed from "HKU\S-1-
5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
to "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run". Startup Programs
11/08/2003 22:37:53 CHANGED desktop.ini
Property "User" changed from ".DEFAULT" to "All
Users". Startup Programs
11/08/2003 22:37:53 CHANGED desktop.ini
Property "Location" changed from "Startup"
to "Common Startup". Startup Programs
11/08/2003 22:37:53 CHANGED desktop.ini
Property "User" changed from "NT AUTHORITY\SYSTEM"
to ".DEFAULT". Startup Programs
11/08/2003 22:37:53 CHANGED desktop.ini
Property "User" changed from "OEM\OEMUSER" to "NT
AUTHORITY\SYSTEM". Startup Programs